Week 8 (extra i guess) Flashcards

1
Q

CPS Vulnerabilities

A

Causes of vulnerabilities include isolation assumption, increased connectivity, heterogeneity, USB usage, bad practices, spying, homogeneity, and suspicious employees.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cyber Vulnerabilities

A

Examples Include:

Inter-control Center Communications Protocol (ICCP),

TCP/IP,

Communication protocols like Modbus.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Physical Vulnerabilities

A

Involves insufficient security for components, susceptibility to tampering, and risks to medical devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Technical Vulnerabilities

A

Arise from human awareness and skill deficiencies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Platform Vulnerabilities

A

Related to configuration, hardware, software, and lack of protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Management Vulnerabilities

A

Due to the absence of security policies and standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

False Data Injection (FDI) Attacks

A

FDI attacks target actuators or sensors in control systems, causing physical impact.

These attacks can lead to significant physical damage, and security mechanisms need to complement traditional technologies like encryption and authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Covert/Stealthy Attacks

A

Challenges in detecting adaptive adversaries aiming to raise pressure without being noticed.

Different types of stealthy FDI attacks, including surge attacks, bias attacks, and geometric attacks, each with varying levels of perturbation and damage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Fuzzing in CPS Security

A

Fuzz testing as an automated method to reveal software defects and vulnerabilities in CPS.

Various fuzzing tools, such as beSTORM, Sulley, SMOD, and modbus-cli, used for testing ICS components.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly